fix(ui,db): harden NULL handling, fix CWE-134, optimize iterations
Some checks failed
CI Code / Code Coverage (push) Failing after 10m34s
CI Code / Check spelling (push) Failing after 10m47s
CI Code / Check coding style (push) Failing after 11m4s
CI Code / Linux (ubuntu) (push) Failing after 11m19s
CI Code / Linux (debian) (push) Failing after 11m28s
CI Code / Linux (arch) (push) Failing after 11m38s

security(CWE-134): fix format string injections + add CI check
fix(ui): subwindow lifecycle, newwin/newpad guards, fallback timestamps
fix(db): sqlite cleanup on failures, sqlite3_close_v2
fix(xmpp): queued_messages loop, barejid leak
perf(core): g_hash_table_iter_init instead of g_hash_table_get_keys
refactor(ui): CLAMP macro in _check_subwin_width
test: XEP-0012 and XEP-0045 functional tests

Author: jabber.developer2
Closes #58, #85
This commit is contained in:
2026-02-06 19:27:40 +01:00
parent f8826b7c79
commit 467222d0ca
36 changed files with 656 additions and 238 deletions

View File

@@ -171,16 +171,15 @@ caps_get_features(void)
{
GList* result = NULL;
GList* features_as_list = g_hash_table_get_keys(prof_features);
GList* curr = features_as_list;
while (curr) {
result = g_list_append(result, strdup(curr->data));
curr = g_list_next(curr);
GHashTableIter iter;
gpointer key, value;
g_hash_table_iter_init(&iter, prof_features);
while (g_hash_table_iter_next(&iter, &key, &value)) {
result = g_list_append(result, strdup((char*)key));
}
g_list_free(features_as_list);
GList* plugin_features = plugins_get_disco_features();
curr = plugin_features;
GList* curr = plugin_features;
while (curr) {
result = g_list_append(result, strdup(curr->data));
curr = g_list_next(curr);

View File

@@ -148,7 +148,7 @@ connection_init(void)
if (string_to_verbosity(v, &verbosity, &err_msg)) {
xmpp_ctx_set_verbosity(conn.xmpp_ctx, verbosity);
} else {
cons_show(err_msg);
cons_show("%s", err_msg);
}
conn.xmpp_conn = xmpp_conn_new(conn.xmpp_ctx);
@@ -638,22 +638,18 @@ gboolean
connection_supports(const char* const feature)
{
gboolean ret = FALSE;
GList* jids = g_hash_table_get_keys(conn.features_by_jid);
GHashTableIter iter;
gpointer key, value;
GList* curr = jids;
while (curr) {
char* jid = curr->data;
GHashTable* features = g_hash_table_lookup(conn.features_by_jid, jid);
g_hash_table_iter_init(&iter, conn.features_by_jid);
while (g_hash_table_iter_next(&iter, &key, &value)) {
GHashTable* features = (GHashTable*)value;
if (features && g_hash_table_lookup(features, feature)) {
ret = TRUE;
break;
}
curr = g_list_next(curr);
}
g_list_free(jids);
return ret;
}
@@ -664,22 +660,17 @@ connection_jid_for_feature(const char* const feature)
return NULL;
}
GList* jids = g_hash_table_get_keys(conn.features_by_jid);
GHashTableIter iter;
gpointer key, value;
GList* curr = jids;
while (curr) {
char* jid = curr->data;
GHashTable* features = g_hash_table_lookup(conn.features_by_jid, jid);
g_hash_table_iter_init(&iter, conn.features_by_jid);
while (g_hash_table_iter_next(&iter, &key, &value)) {
GHashTable* features = (GHashTable*)value;
if (features && g_hash_table_lookup(features, feature)) {
g_list_free(jids);
return jid;
return (const char*)key;
}
curr = g_list_next(curr);
}
g_list_free(jids);
return NULL;
}
@@ -1034,7 +1025,7 @@ _connection_handler(xmpp_conn_t* const xmpp_conn, const xmpp_conn_event_t status
conn.sm_state = xmpp_conn_get_sm_state(conn.xmpp_conn);
if (send_queue_len > 0 && prefs_get_boolean(PREF_STROPHE_SM_RESEND)) {
conn.queued_messages = calloc(send_queue_len + 1, sizeof(*conn.queued_messages));
for (int n = 0; n < send_queue_len && conn.queued_messages[n]; ++n) {
for (int n = 0; n < send_queue_len; ++n) {
conn.queued_messages[n] = xmpp_conn_send_queue_drop_element(conn.xmpp_conn, XMPP_QUEUE_OLDEST);
}
} else if (send_queue_len > 0) {
@@ -1189,12 +1180,13 @@ connection_debug_print_features()
continue;
}
GList* feature_keys = g_hash_table_get_keys(features);
for (GList* l = feature_keys; l != NULL; l = l->next) {
const char* feature = (const char*)l->data;
GHashTableIter feature_iter;
gpointer feature_key, feature_value;
g_hash_table_iter_init(&feature_iter, features);
while (g_hash_table_iter_next(&feature_iter, &feature_key, &feature_value)) {
const char* feature = (const char*)feature_key;
log_debug("%s:\t%s", jid, feature);
}
g_list_free(feature_keys);
}
log_debug("=== End of Features ===");

View File

@@ -437,18 +437,7 @@ form_get_form_type_field(DataForm* form)
gboolean
form_tag_exists(DataForm* form, const char* const tag)
{
GList* tags = g_hash_table_get_keys(form->tag_to_var);
GList* curr = tags;
while (curr) {
if (g_strcmp0(curr->data, tag) == 0) {
g_list_free(tags);
return TRUE;
}
curr = g_list_next(curr);
}
g_list_free(tags);
return FALSE;
return g_hash_table_contains(form->tag_to_var, tag);
}
form_field_type_t

View File

@@ -868,7 +868,7 @@ _handle_error(xmpp_stanza_t* const stanza)
g_string_append(log_msg, " error=");
g_string_append(log_msg, err_msg);
log_info(log_msg->str);
log_info("%s", log_msg->str);
g_string_free(log_msg, TRUE);

View File

@@ -326,7 +326,7 @@ _ox_metadata_result(xmpp_stanza_t* const stanza, void* const userdata)
if (fingerprint) {
if (strlen(fingerprint) == KEYID_LENGTH) {
cons_show(fingerprint);
cons_show("%s", fingerprint);
} else {
cons_show("OX: Wrong char size of public key");
log_error("[OX] Wrong chat size of public key %s", fingerprint);

View File

@@ -455,7 +455,7 @@ _presence_error_handler(xmpp_stanza_t* const stanza)
g_string_append(log_msg, " error=");
g_string_append(log_msg, err_msg);
log_info(log_msg->str);
log_info("%s", log_msg->str);
g_string_free(log_msg, TRUE);